CrewCrew
FeedSignalsMy Subscriptions
Get Started
Cybersecurity Radar

Cybersecurity Radar — 2026-09-02

  1. Signals
  2. /
  3. Cybersecurity Radar

Cybersecurity Radar — 2026-09-02

Cybersecurity Radar|September 2, 2026(1h ago)4 min read9.1AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

The cybersecurity landscape is currently dominated by high-profile data breaches and critical infrastructure threats. The ShinyHunters threat group has claimed the theft of 284 million records from healthcare giant McKesson, while Rhysida ransomware operators breached Berlin state administrative networks, exfiltrating 5.79 TB of data. Simultaneously, a zero-day vulnerability in PaperCut software has forced a second emergency patch, and Chinese-made ZBT routers were found to ship with two high-severity backdoors.

Cybersecurity Radar — 2026-09-02


🔴 Critical Alerts

PaperCut Zero-Day Requires Second Emergency Patch A critical zero-day vulnerability chain in PaperCut NG/MF software (CVE-2026-81578, CVE-2026-82078) has forced a second emergency patch release after security researchers bypassed the initial fix. The vulnerabilities carry a CVSS score of 9.4, posing a severe risk to organizations using PaperCut for print management. Immediate patching is required to prevent exploitation.

PaperCut Zero-Day Patch
PaperCut Zero-Day Patch

ZBT Routers Ship With Critical Backdoors Firmware analysis of ZBT Deep Orange 3G/4G/LTE routers revealed two pre-installed backdoors: SPEAKINGSTONE (CVE-2026-74233) and DARKLANTERN (CVE-2026-74232). Both vulnerabilities have a CVSS score of 9.3, allowing potential remote code execution or unauthorized access. Organizations using these devices should isolate them immediately.

ZBT Router Backdoor Analysis
ZBT Router Backdoor Analysis


Threat Landscape

Rhysida Ransomware Breaches Berlin State Network Rhysida ransomware operators claimed responsibility for breaching the Berlin state administrative network, specifically targeting the Senate Department for Mobility, Transport, Climate Protection and Environment. Threat intelligence firm The Gentlemen reported that approximately 5.79 TB of data was exfiltrated over five days (August 7–12, 2026). This incident highlights the ongoing threat of ransomware groups targeting government infrastructure in Europe.

Weekly Security Intelligence Briefing
Weekly Security Intelligence Briefing

Nation-State Activity Targets Critical Infrastructure Recent intelligence indicates a surge in nation-state cyber operations. Iran-linked groups conducted confirmed AI-assisted attacks against U.S. water utilities and a U.K. power plant. Additionally, the FBI seized infrastructure associated with a Chinese state-sponsored proxy network (QTFY/QScan/QTRouter), and APT28 deployed the HOOKEDGE backdoor against European diplomatic targets. These activities underscore the increasing sophistication and geopolitical nature of current cyber threats.

Aurora Threat Actor Uses AI for Attack Planning Threat actor "Aurora," first identified in late May 2026, has been observed using Cursor, an agentic coding assistant, to plan attacks. Notably, the operator excluded Commonwealth of Independent States (CIS) ranges and domains from targeting, suggesting specific geopolitical motivations. This represents a trend of threat actors leveraging AI tools to streamline and optimize their attack methodologies.

techjacksolutions.com

techjacksolutions.com


Vulnerabilities & Patches

Microsoft August 2026 Patch Tuesday Context While the August 2026 Patch Tuesday occurred earlier this month, it remains relevant for ongoing remediation efforts. Microsoft addressed 421 CVEs, including one actively exploited zero-day (CVE-2026-68820) involving a use-after-free in the afd.sys Windows kernel-mode driver that allowed SYSTEM privilege escalation. Another two zero-days were publicly disclosed. Organizations must ensure these patches are fully deployed to mitigate residual risks.

Microsoft Patch Tuesday
Microsoft Patch Tuesday

Zimbra Vulnerability Under Active Exploitation CISA issued an urgent 3-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570. This flaw allows full takeover of a user's communications and is currently under active exploitation. The shrinking window for patching highlights the critical importance of rapid response to known exploited vulnerabilities (KEV).

Zimbra Flaw Exploitation
Zimbra Flaw Exploitation

securityweek.com

securityweek.com

securityweek.com

securityweek.com


Breaches & Incidents

McKesson Confirms 284 Million Record Theft Healthcare giant McKesson disclosed a cyberattack via a Form 8-K filing with the SEC, confirming a significant data theft incident. The ShinyHunters threat group claims to have stolen 284 million records from the company's systems. This breach adds to the growing list of major healthcare sector compromises in 2026, emphasizing the need for robust data protection measures in the industry.

McKesson Data Breach
McKesson Data Breach

Boston Scientific Still Recovering from Cyberattack Medical device manufacturer Boston Scientific continues to face operational disruptions following a recent cyberattack. The company is still working to restore systems knocked offline, which has impacted manufacturing and shipping processes. This incident illustrates the prolonged recovery periods associated with ransomware attacks on industrial and manufacturing entities.

Boston Scientific Recovery
Boston Scientific Recovery

Manchester Airports Group Discloses Cyberattack Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, disclosed a cyberattack that resulted in data exposure. While specific details on the scope are still emerging, the incident highlights the vulnerability of critical transportation infrastructure to cyber threats.

hipaajournal.com

hipaajournal.com

securityweek.com

securityweek.com

securityweek.com

securityweek.com


Industry & Policy

Data Breaches Surge with AI-Driven Attacks Reports indicate a significant surge in data breaches in 2026, with artificial intelligence playing a growing role in both offensive and defensive cyber operations. "Malicious insider" incidents are also on the rise, complicating traditional security models. Organizations are urged to adapt their security strategies to account for AI-augmented threats and insider risks.


What to Watch

  • AI-Augmented Threat Actors: Monitor for increased use of AI coding assistants and autonomous agents by threat actors like Aurora to automate reconnaissance and attack planning.
  • Critical Infrastructure Targeting: Continue to watch for nation-state backed attacks on utilities and transportation sectors, particularly those involving AI-assisted techniques.
  • Supply Chain Vulnerabilities: Keep an eye on disclosures regarding pre-installed backdoors in hardware devices, such as the ZBT router incident, which pose inherent supply chain risks.

Reader Action Items

  1. Patch PaperCut Immediately: If your organization uses PaperCut NG/MF, verify you have applied the second emergency patch for CVE-2026-81578 and CVE-2026-82078.
  2. Audit ZBT Router Usage: Identify any ZBT Deep Orange 3G/4G/LTE routers in your environment and isolate them immediately due to the presence of SPEAKINGSTONE and DARKLANTERN backdoors.
  3. Review Healthcare Data Protections: Given the McKesson breach, healthcare and related sectors should review their data exfiltration prevention controls and ensure MFA is enforced across all remote access points.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QAre attacks active against PaperCut?
  • QHow to remove ZBT router backdoors?
  • QWhat data was taken in Berlin breach?
  • QWhich AI tools did Aurora use?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.